Direct answer
Do not call an ad account recovered because login, case response, or campaign activity exists. Synthesis/inference: states are non-overlapping: access restored = authorized reachability; operations recovered = all gates pass for a named scope, with provider-dependent affected scope not accepted; outcomes settled = all material ledger differences for a stated cohort/cutoff resolved. Named residuals document work but never settle material differences. Administrative closure may record accepted/not-accepted scopes; it is not operational acceptance. Mutable mechanics require first-party verification. [DRS-A01][BC-S06][BC-S09][RS-S08]
Who this is for
Fit: finance, security, growth, agency, and incident leads after high-spend Meta, Google Ads, TikTok, or cross-platform access, payment, delivery, reporting, verification, automation, or regional incidents.
Not a fit: routine low-risk setup with healthy owner access; anyone seeking an “un-ban,” replacement account, identity/payment rotation, cloaking, forged records, anti-detect tools, appeal spam, indiscriminate chargebacks, or unverified credential handling. Operational—not legal, insurance, tax, banking, forensic, or platform-support advice. AdsInfra makes no recovery, timing, delivery, refund, ROAS, or reimbursement guarantee. [PR-P07][PR-P10][PR-P11]
Decision model
Three labels, not one green check
- Access restored: an authorized owner can reach the relevant surface. This does not establish ownership, clean sessions, partner removal, payment integrity, or connected-asset health. Manager access mechanics and compromised-account routes are not proof every linked asset is clean. [BC-S09][BC-S10][BC-S11]
- Operations recovered: authorized owner administers a named scope; persistence, billing, domains/catalogs/feeds, campaign/rules, measurement, and delivery gates pass. Provider-dependent affected scope remains not accepted. This is an operating synthesis, not a provider definition. [RS-S03][RS-S09][DRS-A01]
- Outcomes settled: all material billed, served-delivery, attribution, analytics, CRM/backend, bank/card, agency, refund, and dispute differences through defined cohort/cutoff are resolved; named residuals do not settle a material difference. [RS-S07][RS-S08]
Preconditions to open the gate
The incident lead must have incident ID/UTC chronology; platform, region, entity, account, asset, and case IDs; last-good export or unavailable note; authorized and finance owners; clean endpoint/security handoff if compromise is plausible; and a current first-party route. Missing any item means not ready. Preserve evidence and route the gap. [DRS-A01][RS-S03][PR-P03][PR-P10][PR-P13]
Hard stop and fail states
Stop and quarantine when access/persistence, authority, read-back, dependency blast radius, provider condition, event/test quality, ledger scope/cutoff, monitoring, or rollback is unresolved. Green status, completed script, or case response does not override these stops. [BC-S06][PR-P11][RS-S07]
Diagnostic or control sequence
Run the sequence in order. Each row names input, owner, action, and stop/branch condition. One approved reversible change at a time; do not mutate budgets, permissions, payments, domains, tracking, or rules concurrently. [RS-S03][RS-S09]
| Step | Evidence/input | Owner | Action | Stop/branch condition |
|---|---|---|---|---|
| 1. Freeze the baseline | Incident record; exact label/error; UTC time; account/object IDs; last-good export; recent-change log; status/case IDs | Incident lead + recorder | Write observed symptom separately from hypotheses. Preserve exports, notices, headers, logs, and unavailable-data notes before cleanup. | Stop if IDs, chronology, or authority cannot be verified. Screenshots remain supplemental context, not the only record. [DRS-A01][RS-S03] |
| 2. Confirm custody and authority | Legal entity; full-control owner; manager/portfolio/business-center links; partner list; billing owner; contract/handoff record | Asset owner | Verify who can add/remove users, export assets, approve spend, and sign closure. Record every unknown as a named task. | Stop if the person requesting changes is not the authorized decision owner. Do not transfer custody by sharing credentials. [BC-S09][VOC-F05] |
| 3. Clean the access plane | Known-clean endpoint; user/admin/partner export; sessions; MFA/recovery contacts; OAuth apps; tokens; extensions; security notices | Security/asset owner | Reset password/MFA/recovery contacts where applicable; revoke specifically identified suspect sessions/tokens/apps; compare before/after access. | Stop if endpoint compromise is suspected, revocation fails, or an unknown administrator persists. Route to security/first-party recovery; do not relaunch. [BC-S10][BC-S11][PR-P12][BC-S18] |
| 4. Validate payment and billing authority | Platform balance/invoice/transaction IDs; bank/card record; agency invoice; authorized-user list; served-delivery period | Finance owner | Branch: suspected unauthorized activity; legitimate platform-balance disagreement; or agency/reseller invoice mismatch. Reconcile identifiers before choosing platform, issuer, bank, or counsel route. | Stop a dispute if authorization, entity, currency, period, or transaction mapping is unresolved. Google warns that a chargeback against a legitimate Google Ads balance can lead to suspension; keep this account-specific and do not treat it as issuer advice. [PR-P11][BC-S08] |
| 5. Map shared dependencies | Parent/child containers; payment profile; domain/endpoint; catalog/feed; pixel/dataset; conversion configuration; vendors; rules/scripts/automations | Operations executor + asset owner | Compare the dependency graph with the incident scope. Record affected assets, owner, rollback, and independent health check for each shared object. | Stop if disabling, rotating, or deleting one object could affect another entity/campaign and no owner-approved rollback exists. Synthesis/inference: nominally separate accounts are not independent when dependencies are shared. [RS-S17][RS-S18] |
| 6. Reconcile campaign and rule state | Preserved before-state; current campaigns/ad groups/ads; budgets/bids; targeting; creatives; feeds; rules/scripts; automation logs | Operations executor | Produce a change diff. For every intended mutation, perform platform read-back; treat a completed Google Ads Script run as insufficient because execution is best-effort. | Stop if unexpected budget, destination, creative, targeting, rule, or feed changes remain unexplained. Roll back only through an authorized, bounded change. [BC-S06] |
| 7. Validate measurement and destination | Event schema/version; consent state; event samples/IDs; tag/API diagnostics; landing endpoint; analytics; CRM/backend record | Measurement owner | Test destination/event through deduplication and the defined business record. Define cohort, timezone, attribution window, and settlement cutoff before comparing counts. | Stop if events are stale, duplicated, misconfigured, consent-invalid, or untraceable. Do not call a metric gap a settled loss or platform cause. [RS-S07][RS-S08] |
| 8. Run a bounded conversion test | Approved test destination/campaign; unique test event/order/lead marker; expected record; owner-approved spend ceiling; alert recipient | Asset owner + measurement owner | Run a low-risk authorized test in an approved mode where currently supported. Tag it; suppress unintended fulfillment/payment/customer communication and optimization/audience downstreams; exclude it from settlement cohorts and optimization inputs; verify no side effect; preserve evidence before cleanup. | Stop on unauthorized spend, wrong destination, missing/duplicate event, unexpected audience/creative, side effect, or alert failure. Test mechanics require first-party verification. [RS-S07][RS-S08] |
| 9. Reconcile incident-period ledgers | Platform-billed; served delivery; platform attribution; analytics/events; CRM/backend; bank/card; agency invoice | Finance owner + measurement owner | Freeze versioned extracts to the incident cohort and cutoff before restart. Record matches, latency, consent/attribution limits, disputed amounts, and residual owners; this checkpoint does not settle the later restart window. | Status remains outcomes unsettled if any material difference is unresolved. Do not imply reimbursement or causality. [RS-S08] |
| 10. Monitor a limited restart | Test result; spend/delivery/event/access alerts; rollback threshold; communication plan | Incident lead | Approve a staged, low-risk restart within authority and start the observation window. Watch spend, delivery, events, destinations, permissions, and incident signals; document read-back. | Roll back or pause on any stop condition, alert gap, unauthorized change, or unexplained divergence. Platform delivery remains provider-dependent. [RS-S07][RS-S09] |
| 11. Reconcile restart window | Versioned restart extracts; restart spend/delivery; events; attribution; analytics; CRM/backend; bank/card; agency records; post-restart cutoff | Finance owner + measurement owner | After the observation window, freeze new extracts for the restart cohort/cutoff. Isolate seeded test artifacts and reconcile all material differences; update residuals. | Outcomes remain unsettled if any material difference is unresolved. Administrative closure may record this scope as not accepted, but cannot upgrade it. [RS-S08] |
| 12. Sign administrative closure and hand back | Evidence index; both reconciliation checkpoints; acceptance results; residual register; monitoring owner; follow-up dates | Asset owner + finance owner + incident lead | Sign accepted scope and separately record not accepted or outcomes unsettled scope, provider dependency, test cleanup, and next review; hand back decisions and revoke temporary access. | No operational acceptance signature if residuals lack owner/action or monitoring is inactive. Administrative closure records status; it does not prove recovery or settled outcomes. [RS-S10][RS-S03] |
Rollback logic
Before each change, record expected state, approver, rollback, signal, and blast radius. If read-back disagrees, stop; do not “fix forward.” Roll back only to an approved prior state that will not damage shared dependencies. If rollback is impossible/provider-controlled, quarantine spend/data, document the case, and escalate; never delete evidence. Synthesis/inference from [DRS-A01][RS-S09][BC-S06].
Evidence packet (minimum, no secrets)
- Incident ID, collector, UTC timestamps, timezone, platform/surface, region, entity, account/container/object IDs, and exact labels/errors.
- Last-good/current exports for access, campaigns, rules, billing, delivery, measurement, domains/catalogs/feeds, and parent/child links.
- User/admin/partner/session/app/token changes; notices; headers; request IDs; case chronology; and attempted actions with expected/actual read-back.
- Invoice/balance/transaction IDs, bank/card references, agency invoice, owner review, served-delivery, event samples, backend settlement, and cohort definition.
- Evidence location, retention/access owner, redactions, unavailable records, and verification owner. Never send passwords, MFA codes, cookies, government IDs, full payment numbers, remote-control access, or scripts. [DRS-A01][BC-S18]
Post-recovery monitoring and review
For restart, assign owner, signals, frequency, alert recipient, and stop thresholds. Monitor spend/payment, delivery/budget, events/backend, destination/domain/catalog/feed, access/apps/tokens, automation read-backs, and symptom. Synthesis/inference: use actionable alerts. [RS-S07]
After the owner-selected observation window, hold a blameless review for material impact, unauthorized change, failed monitoring, or recovery beyond the objective; record chronology, evidence gaps, control changes, owners/dates, and a proving test. [RS-S09][RS-S10]
Evidence to preserve
Use the packet as closeout index. Preserve the before-state before changing shared objects; retain raw/read-only exports where permitted with collector, time, source, redaction, and access history. Apply privacy, retention, legal-hold, and provider terms; this is not a forensic mandate. [DRS-A01][RS-S03]
What not to do
Do not bypass restrictions with replacement/rented accounts, identity/payment rotation, cloaking, forged records, anti-detect tools, appeal spam, or speculative allegations. Do not trust unsolicited recovery messages or provide credentials, cookies, MFA codes, full payment data, government IDs, remote control, or scripts. Do not give blanket chargeback advice or relaunch on a green status, working login, completed script, or case reply. [PR-P07][PR-P10][BC-S06][PR-P11][BC-S18]
When to escalate
Self-service: healthy owner access, clear low-risk state, reversible change, specific first-party action. Platform: current review, security, billing, verification, or Account Health route. Finance/issuer/bank: authorization or settlement. Security/forensics: endpoint, session, token, or unauthorized activity. Counsel/broker/insurer: legal, contract, evidence-hold, or coverage questions. Country/region can affect TikTok business-verification document requirements, while TikTok transaction-appeal eligibility is case-by-case and can differ by account type; specialists cannot control provider outcomes. [PR-P03][PR-P10][PR-P11][PR-P13][PR-P14][PR-P15]
FAQ
Is a successful login recovery?
No. It is access restored only. Confirm authority, sessions/apps, partners, payment, dependencies, campaign/rule state, events, test conversion, monitoring, and sign-off before calling operations recovered. [BC-S09][BC-S10]
Can a platform case response close the incident?
No. It proves provider communication, not ownership, persistence, delivery, measurement, settled finance, or future eligibility. TikTok transaction-appeal eligibility is case-by-case and can differ by account type; do not infer regional appeal eligibility from PR-P15. [PR-P03][PR-P10][PR-P15]
Should we increase budget to test recovery?
No generic increase is justified. Use an owner-approved bounded test with a stop condition and independent event/backend read-back; it is not permission to resume normal spend. Synthesis/inference. [RS-S07][RS-S08]
When are outcomes settled?
Only when all material records reconcile to the same cohort and cutoff. Named owners, limitations, and next actions document unresolved differences but do not settle them. [RS-S08]
What if one dependency is still provider-dependent?
Mark operations not accepted for the affected scope and outcomes unsettled where material differences remain; quarantine restart and record the residual. Administrative closure cannot change those states. Do not conceal the dependency by relinking or creating a replacement account. [PR-P10][PR-P13]
Source appendix
All sources were accessed 2026-07-19.
| Key | Source title; author/publisher; publication date | URL |
|---|---|---|
| RS-S03 | Cybersecurity Incident & Vulnerability Response Playbooks; CISA; 2021 | https://www.cisa.gov/sites/default/files/2024-08/Federal_Government_Cybersecurity_Incident_and_Vulnerability_Response_Playbooks_508C.pdf |
| RS-S07 | Monitoring Distributed Systems; Rob Ewaschuk, Google SRE; 2017 | https://sre.google/sre-book/monitoring-distributed-systems/ |
| RS-S08 | Service Level Objectives; Chris Jones, John Wilkes, Niall Murphy, Cody Smith, Google SRE; 2017 | https://sre.google/sre-book/service-level-objectives/ |
| RS-S09 | Managing Incidents; Andrew Stribblehill, Google SRE; 2017 | https://sre.google/sre-book/managing-incidents/ |
| RS-S10 | Postmortem Culture: Learning from Failure; John Lunney and Sue Lueder, Google SRE; 2017 | https://sre.google/sre-book/postmortem-culture/ |
| RS-S17 | Mapping Disruption Sources in the Power Grid and Implications for Resilience; Maureen S. Golan and Javad Mohammadi; arXiv; 2022-07-17 | https://arxiv.org/abs/2207.08146 |
| RS-S18 | Comparative Resilience Notions and Vertex Attack Tolerance of Scale-Free Networks; John Matta, Jeffrey Borwey, Gunes Ercal; arXiv; 2014-04-01 | https://arxiv.org/abs/1404.0103 |
| PR-P03 | Request a review if you are restricted from advertising on Meta platforms; Meta; undated | https://www.facebook.com/business/help/530209463124901/ |
| PR-P07 | Meta Takes Legal Action Against Scam Advertisers; Meta Newsroom; 2026-02-26 | https://about.fb.com/news/2026/02/meta-takes-legal-action-against-scam-advertisers/ |
| PR-P10 | Google Ads account suspensions overview; Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/9841640?hl=en |
| PR-P11 | Billing and payment suspensions; Google Ads Help; current/undated | https://support.google.com/adspolicy/answer/13704200?hl=en |
| PR-P12 | Secure your Google Ads account: Introduction; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/2375456 |
| PR-P13 | About suspended ad accounts on TikTok; TikTok for Business; updated June 2026 | https://ads.tiktok.com/help/article/account-suspensions?redirected=1 |
| PR-P14 | How to verify your business on TikTok; TikTok for Business; updated May 2026 | https://ads.tiktok.com/help/article/about-business-verification?aadvid=72391499277 |
| PR-P15 | About transaction-related appeals; TikTok for Business; updated July 2026 | https://ads.tiktok.com/help/article/about-transaction-related-appeals |
| BC-S06 | Errors and Warnings; Google Ads Scripts team; updated 2026-06-24 | https://developers.google.com/google-ads/scripts/docs/troubleshooting/errors |
| BC-S08 | How to dispute a Google Ads charge; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/10560092 |
| BC-S09 | Manager Accounts (MCC): About Google Ads manager accounts; Google Ads Help; current/undated | https://support.google.com/google-ads/answer/6139186 |
| BC-S10 | If your account was hacked or someone is using it without your permission; Meta; current/undated | https://www.meta.com/help/policies/539039418231124/ |
| BC-S11 | Recover a hacked or compromised business portfolio; Meta Business Help Center; current/undated | https://www.facebook.com/business/help/25302697499431030 |
| BC-S18 | Tech (non)support: Scammers pose as Meta in Facebook account grab ploy; Sharef Hlal and Karam Chatra, Group-IB; 2023-04-25 | https://www.group-ib.com/blog/meta-phishing-campaign/ |
| DRS-A01 | Digital Evidence Preservation: Considerations for Evidence Handlers; Barbara Guttman, Douglas R. White, Tracy Walraven, NIST; 2022-09 | https://nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8387.pdf |
| VOC-F05 | Sole Business Portfolio admin permanently disabled; u/Exact_Kiwi3437, Reddit; 2026-07-16 | https://old.reddit.com/r/FacebookAds/comments/1uxske3/sole_business_portfolio_admin_permanently/ |
Related resources
- Facebook Business Account Hacked — Recovery GuideYour Facebook Business account has been hacked. Unauthorized campaigns are running, your budget is being drained, and your pages may have been transferred. Here's how to regain control immediately.
- Google Ads Account Suspended — Recovery GuideYour Google Ads account has been suspended. Here's why, how to appeal, and what to do to get back to running campaigns on Google Ads.
- Google Ads Account Suspended for Billing — Fix GuideYour Google Ads account has been suspended due to a billing issue — failed payment, suspected fraud, or expired card. Here's how to identify the exact issue and get your account back.
- Google Ads Suspension Recovery — The Full RoadmapA step-by-step roadmap for recovering from a Google Ads suspension: how to triage the suspension type, which appeal channel to use, realistic timelines, and what to do if the appeal fails.
- TikTok Ad Account Suspended — Recovery GuideYour TikTok ad account has been suspended. Here's why it happened, how to recover, and how to prevent future suspensions on TikTok Ads Manager.
- How To Appeal a TikTok Ad Account SuspensionStep-by-step guide to appealing a TikTok Ads Manager suspension. Includes appeal templates, escalation paths, and whitelist strategies.
- TikTok Ads Not Delivering? Diagnose Zero ImpressionsTikTok ads approved but not delivering or spending? Check delivery status, billing, schedule, audience, bid, budget, and creative before making changes.
- Meta Pixel Not Firing — Troubleshooting GuideYour Meta Pixel is not firing or firing inconsistently. Here's how to diagnose the issue, fix broken tracking, and restore your conversion data and retargeting audiences.
- Ad Account Ownership & Access Audit for High-Spend OperationsMap legal ownership, platform roles, admin access, custody, dependencies, tokens, partners, and safe offboarding before an ad incident.
- Ad Account Billing Interruption Reconciliation: Balance, Authorization, and RevenueReconcile ad balances, payment rails, agencies, credits, disputes, attribution, and revenue without premature chargebacks.
- Ad Incident Evidence Capture Guide: Preserve the Record Before You Change the SystemPreserve ad evidence before changing access, billing, campaigns, tracking, domains, catalogs, integrations, or appeals.
- Ads Not Delivering: A Zero-Spend Diagnosis Across Meta, Google, and TikTokZero reports, impressions, conversions, and delivery failure for a frozen scope: an evidence-first decision tree.
- Ad Account Suspended: Incident Response ChecklistA platform-neutral suspension runbook: classify the state, preserve evidence, contain safely, reconcile billing, verify recovery, and restart with monitoring.
Contact AdsInfra
Send a message about this resource before making a high-impact change.